{"cves":[{"id":"CVE-2006-2016","published":"2006-04-25T12:50:00","updated_at":"2025-07-17T16:38:29.230328+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in phpLDAPadmin 0.9.8\nand earlier allow remote attackers to inject arbitrary web script or HTML\nvia the (1) dn parameter in (a) compare_form.php, (b) copy_form.php, (c)\nrename_form.php, (d) template_engine.php, and (e) delete_form.php; (2)\nscope parameter in (f) search.php; and (3) Container DN, (4) Machine Name,\nand (5) UID Number fields in (g) template_engine.php.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-2016"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"phpldapadmin","source":"https://ubuntu.com/security/cve?package=phpldapadmin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpldapadmin","debian":"https://tracker.debian.org/pkg/phpldapadmin","statuses":[{"release_codename":"dapper","status":"released","description":"0.9.8.3-1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.9.8.3-1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.9.8.3-1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.9.8.3-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-1993","published":"2006-04-25T12:50:00","updated_at":"2025-07-17T16:38:29.230328+00:00","description":"\nMozilla Firefox 1.5.0.2, when designMode is enabled, allows remote\nattackers to cause a denial of service and possibly execute arbitrary code\nvia certain Javascript that is not properly handled by the\ncontentWindow.focus method in an iframe, which causes a reference to a\ndeleted controller context object. NOTE: this was originally claimed to be\na buffer overflow in (1) js320.dll and (2) xpcom_core.dll, but the vendor\ndisputes this claim.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-1993"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.0.6+0dfsg-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.0.6+1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"firefox-granparadiso","source":"https://ubuntu.com/security/cve?package=firefox-granparadiso","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-granparadiso","debian":"https://tracker.debian.org/pkg/firefox-granparadiso","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lightning-sunbird","source":"https://ubuntu.com/security/cve?package=lightning-sunbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lightning-sunbird","debian":"https://tracker.debian.org/pkg/lightning-sunbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"midbrowser","source":"https://ubuntu.com/security/cve?package=midbrowser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=midbrowser","debian":"https://tracker.debian.org/pkg/midbrowser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-1940","published":"2006-04-25T12:50:00","updated_at":"2025-07-17T16:38:29.230328+00:00","description":"\nUnspecified vulnerability in Ethereal 0.10.4 up to 0.10.14 allows remote\nattackers to cause a denial of service (abort) via the SNDCP dissector.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-1940"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"dapper","status":"released","description":"0.99.0-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-1939","published":"2006-04-25T12:50:00","updated_at":"2025-07-17T16:38:29.230328+00:00","description":"\nMultiple unspecified vulnerabilities in Ethereal 0.9.x up to 0.10.14 allow\nremote attackers to cause a denial of service (crash from null dereference)\nvia (1) an invalid display filter, or the (2) GSM SMS, (3) ASN.1-based, (4)\nDCERPC NT, (5) PER, (6) RPC, (7) DCERPC, and (8) ASN.1 dissectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-1939"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"dapper","status":"released","description":"0.99.0-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-1938","published":"2006-04-25T12:50:00","updated_at":"2025-07-17T16:38:29.230328+00:00","description":"\nMultiple unspecified vulnerabilities in Ethereal 0.8.x up to 0.10.14 allow\nremote attackers to cause a denial of service (crash from null dereference)\nvia the (1) Sniffer capture or (2) SMB PIPE dissector.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-1938"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"released","description":"0.99.0-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-1937","published":"2006-04-25T12:50:00","updated_at":"2025-07-17T16:38:27.664747+00:00","description":"\nMultiple unspecified vulnerabilities in Ethereal 0.10.x up to 0.10.14 allow\nremote attackers to cause a denial of service (crash from null dereference)\nvia (1) multiple vectors in H.248, and the (2) X.509if, (3) SRVLOC, (4)\nH.245, (5) AIM, and (6) general packet dissectors; and (7) the statistics\ncounter.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-1937"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"dapper","status":"released","description":"0.99.0-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-1936","published":"2006-04-25T12:50:00","updated_at":"2025-07-17T16:38:27.664747+00:00","description":"\nBuffer overflow in Ethereal 0.8.5 up to 0.10.14 allows remote attackers to\nexecute arbitrary code via the telnet dissector.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-1936"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"dapper","status":"released","description":"0.99.0-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-1935","published":"2006-04-25T12:50:00","updated_at":"2025-07-17T16:38:27.664747+00:00","description":"\nBuffer overflow in Ethereal 0.9.15 up to 0.10.14 allows remote attackers to\ncause a denial of service (crash) and possibly execute arbitrary code via\nthe COPS dissector.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-1935"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"dapper","status":"released","description":"0.99.0-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-1934","published":"2006-04-25T12:50:00","updated_at":"2025-07-17T16:38:27.664747+00:00","description":"\nMultiple buffer overflows in Ethereal 0.10.x up to 0.10.14 allow remote\nattackers to cause a denial of service (crash) and possibly execute\narbitrary code via the (1) ALCAP dissector, (2) Network Instruments file\ncode, or (3) NetXray/Windows Sniffer file code.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-1934"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"dapper","status":"released","description":"0.99.0-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-1933","published":"2006-04-25T12:50:00","updated_at":"2025-07-17T16:38:27.664747+00:00","description":"\nMultiple unspecified vulnerabilities in Ethereal 0.10.x up to 0.10.14 allow\nremote attackers to cause a denial of service (large or infinite loops)\nviarafted packets to the (1) UMA and (2) BER dissectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-1933"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"dapper","status":"released","description":"0.99.0-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-1932","published":"2006-04-25T12:50:00","updated_at":"2025-07-17T16:38:27.664747+00:00","description":"\nOff-by-one error in the OID printing routine in Ethereal 0.10.x up to\n0.10.14 has unknown impact and remote attack vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-1932"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"dapper","status":"released","description":"0.99.0-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-1513","published":"2006-04-25T12:50:00","updated_at":"2025-07-17T16:38:07.873757+00:00","description":"\nMultiple buffer overflows in abc2ps before 1.3.3 allow user-assisted\nattackers to execute arbitrary code via crafted ABC music files.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-1513"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"abc2ps","source":"https://ubuntu.com/security/cve?package=abc2ps","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=abc2ps","debian":"https://tracker.debian.org/pkg/abc2ps","statuses":[{"release_codename":"dapper","status":"released","description":"1.3.3-3sarge1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.3.3-3sarge1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-1057","published":"2006-04-25T01:02:00","updated_at":"2025-07-17T16:37:51.245515+00:00","description":"\nRace condition in daemon/slave.c in gdm before 2.14.1 allows local users to\ngain privileges via a symlink attack when gdm performs chown and chgrp\noperations on the .ICEauthority file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-278-1","https://www.cve.org/CVERecord?id=CVE-2006-1057"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"gdm","source":"https://ubuntu.com/security/cve?package=gdm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gdm","debian":"https://tracker.debian.org/pkg/gdm","statuses":[{"release_codename":"dapper","status":"released","description":"2.14.10-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.16.1-0ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.18.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-278-1"],"notices":[{"id":"USN-278-1","title":"gdm vulnerability","summary":"gdm vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2006-05-04T01:35:56","description":"Marcus Meissner discovered a race condition in gdm's handling of the\n~/.ICEauthority file permissions. A local attacker could exploit this\nto become the owner of an arbitrary file in the system. When getting\ncontrol over automatically executed scripts (like cron jobs), the\nattacker could eventually leverage this flaw to execute arbitrary\ncommands with root privileges.","is_hidden":false,"release_packages":{"hoary":[{"name":"gdm","version":"","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"gdm","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-1057"]}]},{"id":"CVE-2006-1991","published":"2006-04-24T23:02:00","updated_at":"2025-07-17T16:38:29.230328+00:00","description":"\nThe substr_compare function in string.c in PHP 5.1.2 allows\ncontext-dependent attackers to cause a denial of service (memory access\nviolation) via an out-of-bounds offset argument.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-320-1","https://www.cve.org/CVERecord?id=CVE-2006-1991"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php4","source":"https://ubuntu.com/security/cve?package=php4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php4","debian":"https://tracker.debian.org/pkg/php4","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.1.6-1ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-320-1"],"notices":[{"id":"USN-320-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2006-07-19T22:58:47","description":"The phpinfo() PHP function did not properly sanitize long strings. A\nremote attacker could use this to perform cross-site scripting attacks\nagainst sites that have publicly-available PHP scripts that call\nphpinfo(). Please note that it is not recommended to publicly expose\nphpinfo(). (CVE-2006-0996)\n\nAn information disclosure has been reported in the\nhtml_entity_decode() function. A script which uses this function to\nprocess arbitrary user-supplied input could be exploited to expose a\nrandom part of memory, which could potentially reveal sensitive data.\n(CVE-2006-1490)\n\nThe wordwrap() function did not sufficiently check the validity of the\n'break' argument. An attacker who could control the string passed to\nthe 'break' parameter could cause a heap overflow; however, this\nshould not happen in practical applications. (CVE-2006-1990)\n\nThe substr_compare() function did not sufficiently check the validity\nof the 'offset' argument. A script which passes untrusted user-defined\nvalues to this parameter could be exploited to crash the PHP\ninterpreter. (CVE-2006-1991)\n\nIn certain situations, using unset() to delete a hash entry could\ncause the deletion of the wrong element, which would leave the\nspecified variable defined. This could potentially cause information\ndisclosure in security-relevant operations. (CVE-2006-3017)\n\nIn certain situations the session module attempted to close a data\nfile twice, which led to memory corruption. This could potentially be\nexploited to crash the PHP interpreter, though that could not be\nverified. (CVE-2006-3018)\n\nThis update also fixes various bugs which allowed local scripts\nto bypass open_basedir and 'safe mode' restrictions by passing special\narguments to tempnam() (CVE-2006-1494, CVE-2006-2660), copy()\n(CVE-2006-1608), the curl module (CVE-2006-2563), or error_log()\n(CVE-2006-3011).","is_hidden":false,"release_packages":{"dapper":[{"name":"php5-cli","version":"5.1.2-1ubuntu3.1","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.1","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.1","is_source":false,"source_link":"","version_link":""},{"name":"php5-curl","version":"5.1.2-1ubuntu3.1","is_source":false,"source_link":"","version_link":""}],"hoary":[{"name":"libapache2-mod-php4","version":"4:4.3.10-10ubuntu4.5","is_source":false,"source_link":"","version_link":""},{"name":"php4-cgi","version":"4:4.3.10-10ubuntu4.5","is_source":false,"source_link":"","version_link":""},{"name":"php4-cli","version":"4:4.3.10-10ubuntu4.5","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"php5-cli","version":"5.0.5-2ubuntu1.3","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.0.5-2ubuntu1.3","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.0.5-2ubuntu1.3","is_source":false,"source_link":"","version_link":""},{"name":"php5-curl","version":"5.0.5-2ubuntu1.3","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-1494","CVE-2006-3011","CVE-2006-1490","CVE-2006-1608","CVE-2006-2563","CVE-2006-1991","CVE-2006-1990","CVE-2006-2660","CVE-2006-0996","CVE-2006-3018","CVE-2006-3016"]}]},{"id":"CVE-2006-1990","published":"2006-04-24T00:00:00","updated_at":"2025-07-17T16:38:29.230328+00:00","description":"\nInteger overflow in the wordwrap function in string.c in PHP 4.4.2 and\n5.1.2 might allow context-dependent attackers to execute arbitrary code via\ncertain long arguments that cause a small buffer to be allocated, which\ntriggers a heap-based buffer overflow in a memcpy function call, a\ndifferent vulnerability than CVE-2002-1396.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-320-1","https://www.cve.org/CVERecord?id=CVE-2006-1990"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php4","source":"https://ubuntu.com/security/cve?package=php4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php4","debian":"https://tracker.debian.org/pkg/php4","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"4.4.2-1.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.1.6-1ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"5.2.3-1ubuntu5","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.2.3-1ubuntu5","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"5.2.3-1ubuntu5","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"5.2.3-1ubuntu5","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"5.2.3-1ubuntu5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-320-1"],"notices":[{"id":"USN-320-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2006-07-19T22:58:47","description":"The phpinfo() PHP function did not properly sanitize long strings. A\nremote attacker could use this to perform cross-site scripting attacks\nagainst sites that have publicly-available PHP scripts that call\nphpinfo(). Please note that it is not recommended to publicly expose\nphpinfo(). (CVE-2006-0996)\n\nAn information disclosure has been reported in the\nhtml_entity_decode() function. A script which uses this function to\nprocess arbitrary user-supplied input could be exploited to expose a\nrandom part of memory, which could potentially reveal sensitive data.\n(CVE-2006-1490)\n\nThe wordwrap() function did not sufficiently check the validity of the\n'break' argument. An attacker who could control the string passed to\nthe 'break' parameter could cause a heap overflow; however, this\nshould not happen in practical applications. (CVE-2006-1990)\n\nThe substr_compare() function did not sufficiently check the validity\nof the 'offset' argument. A script which passes untrusted user-defined\nvalues to this parameter could be exploited to crash the PHP\ninterpreter. (CVE-2006-1991)\n\nIn certain situations, using unset() to delete a hash entry could\ncause the deletion of the wrong element, which would leave the\nspecified variable defined. This could potentially cause information\ndisclosure in security-relevant operations. (CVE-2006-3017)\n\nIn certain situations the session module attempted to close a data\nfile twice, which led to memory corruption. This could potentially be\nexploited to crash the PHP interpreter, though that could not be\nverified. (CVE-2006-3018)\n\nThis update also fixes various bugs which allowed local scripts\nto bypass open_basedir and 'safe mode' restrictions by passing special\narguments to tempnam() (CVE-2006-1494, CVE-2006-2660), copy()\n(CVE-2006-1608), the curl module (CVE-2006-2563), or error_log()\n(CVE-2006-3011).","is_hidden":false,"release_packages":{"dapper":[{"name":"php5-cli","version":"5.1.2-1ubuntu3.1","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.1","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.1","is_source":false,"source_link":"","version_link":""},{"name":"php5-curl","version":"5.1.2-1ubuntu3.1","is_source":false,"source_link":"","version_link":""}],"hoary":[{"name":"libapache2-mod-php4","version":"4:4.3.10-10ubuntu4.5","is_source":false,"source_link":"","version_link":""},{"name":"php4-cgi","version":"4:4.3.10-10ubuntu4.5","is_source":false,"source_link":"","version_link":""},{"name":"php4-cli","version":"4:4.3.10-10ubuntu4.5","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"php5-cli","version":"5.0.5-2ubuntu1.3","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.0.5-2ubuntu1.3","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.0.5-2ubuntu1.3","is_source":false,"source_link":"","version_link":""},{"name":"php5-curl","version":"5.0.5-2ubuntu1.3","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-1494","CVE-2006-3011","CVE-2006-1490","CVE-2006-1608","CVE-2006-2563","CVE-2006-1991","CVE-2006-1990","CVE-2006-2660","CVE-2006-0996","CVE-2006-3018","CVE-2006-3016"]}]},{"id":"CVE-2006-1865","published":"2006-04-21T23:06:00","updated_at":"2025-07-17T16:38:25.964582+00:00","description":"\nArgument injection vulnerability in Beagle before 0.2.5 allows attackers to\nexecute arbitrary commands via crafted filenames that inject command line\narguments when Beagle launches external helper applications while indexing.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-1865"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"beagle","source":"https://ubuntu.com/security/cve?package=beagle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=beagle","debian":"https://tracker.debian.org/pkg/beagle","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-1945","published":"2006-04-20T22:02:00","updated_at":"2025-07-17T16:38:29.230328+00:00","description":"\nCross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.5 and\nearlier allows remote attackers to inject arbitrary web script or HTML via\nthe config parameter. NOTE: this might be the same core issue as\nCVE-2005-2732.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-1945"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"awstats","source":"https://ubuntu.com/security/cve?package=awstats","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=awstats","debian":"https://tracker.debian.org/pkg/awstats","statuses":[{"release_codename":"dapper","status":"released","description":"6.5-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-1942","published":"2006-04-20T22:02:00","updated_at":"2025-07-17T16:38:29.230328+00:00","description":"\nMozilla Firefox 1.5.0.2 and possibly other versions before 1.5.0.4,\nNetscape 8.1, 8.0.4, and 7.2, and K-Meleon 0.9.13 allows user-assisted\nremote attackers to open local files via a web page with an IMG element\ncontaining a SRC attribute with a non-image file:// URL, then tricking the\nuser into selecting View Image for the broken image, as demonstrated using\na .wma file to launch Windows Media Player, or by referencing an \"alternate\nweb page.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-1942"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-1931","published":"2006-04-20T21:02:00","updated_at":"2025-07-17T16:38:27.664747+00:00","description":"\nThe HTTP/XMLRPC server in Ruby before 1.8.2 uses blocking sockets, which\nallows attackers to cause a denial of service (blocked connections) via a\nlarge amount of data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-273-1","https://www.cve.org/CVERecord?id=CVE-2006-1931"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ruby1.8","source":"https://ubuntu.com/security/cve?package=ruby1.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby1.8","debian":"https://tracker.debian.org/pkg/ruby1.8","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-273-1"],"notices":[{"id":"USN-273-1","title":"Ruby vulnerability","summary":"Ruby vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2006-04-24T22:57:34","description":"Yukihiro Matsumoto reported that Ruby's HTTP module uses blocking\nsockets. By sending large amounts of data to a server application that\nuses this module, a remote attacker could exploit this to render this\napplication unusable and not respond any more to other clients (Denial\nof Service).","is_hidden":false,"release_packages":{"hoary":[{"name":"libruby1.8","version":"","is_source":false,"source_link":"","version_link":""},{"name":"libwebrick-ruby1.8","version":"","is_source":false,"source_link":"","version_link":""}],"warty":[{"name":"libruby1.8","version":"","is_source":false,"source_link":"","version_link":""},{"name":"libwebrick-ruby1.8","version":"","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"libruby1.8","version":"","is_source":false,"source_link":"","version_link":""},{"name":"libwebrick-ruby1.8","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-1931"]}]},{"id":"CVE-2006-1905","published":"2006-04-20T10:02:00","updated_at":"2025-07-17T16:38:27.664747+00:00","description":"\nMultiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.3\nallow remote attackers to execute arbitrary code via format string\nspecifiers in a long filename on an EXTINFO line in a playlist file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-1905"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"xine-ui","source":"https://ubuntu.com/security/cve?package=xine-ui","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xine-ui","debian":"https://tracker.debian.org/pkg/xine-ui","statuses":[{"release_codename":"dapper","status":"released","description":"0.99.4-0ubuntu6","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.99.4-0ubuntu6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.99.4-0ubuntu6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":77600,"limit":20,"total_results":79316}